diff --git a/security/vuxml/vuln/2024.xml b/security/vuxml/vuln/2024.xml index 59130ea7061..1b1598b3d95 100644 --- a/security/vuxml/vuln/2024.xml +++ b/security/vuxml/vuln/2024.xml @@ -1,3 +1,39 @@ + + Gitlab -- Vulnerabilities + + + gitlab-ce + gitlab-ee + 17.2.017.2.1 + 17.1.017.1.3 + 12.0.017.0.5 + + + + +

Gitlab reports:

+
+

XSS via the Maven Dependency Proxy

+

Project level analytics settings leaked in DOM

+

Reports can access and download job artifacts despite use of settings to prevent it

+

Direct Transfer - Authorised project/group exports are accessible to other users

+

Bypassing tag check and branch check through imports

+

Project Import/Export - Make project/group export files hidden to everyone except user who initiated it

+
+ +
+ + CVE-2024-5067 + CVE-2024-7057 + CVE-2024-0231 + https://about.gitlab.com/releases/2024/07/24/patch-release-gitlab-17-2-1-released/ + + + 2024-07-24 + 2024-07-25 + +
+ electron29 -- multiple vulnerabilities